EtwpReadPerSiloConfigParameters

NTSTATUS __fastcall EtwpReadPerSiloConfigParameters(INT64 a1, INT64 a2, WCHAR a3){
  NTSTATUS v4; 
  void *v5; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  int v8; 
  unsigned int *v9; 
  _RTL_QUERY_REGISTRY_TABLE result[2]; 
  unsigned int v11; 
  void *KeyHandle; 
  KeyHandle = 0i64;
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  v11 = 64;
  DestinationString = 0i64;
  RtlInitUnicodeString(&DestinationString, L"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\WMI", a3);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = &DestinationString;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 576;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  if( ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes) < 0
    || (memset((INT64)result, 0i64),
        result[0].QueryRoutine = (int(__fastcall *)(wchar_t *, unsigned int, void *, unsigned int, void *, void *))EtwpQueryRegistryCallback,
        result[0].EntryContext = &v8,
        result[0].Name = L"EtwMaxLoggers",
        result[0].DefaultType = 4,
        v8 = 4,
        v9 = &v11,
        (int)RtlQueryRegistryValuesEx(0x40000000ui64, (const WCHAR *)KeyHandle, result, 0i64, 0i64) < 0) )
  {
    v4 = v11;
  }
  else
  {
    v4 = 256;
    if( v11 <= 0x100 )
    {
      v4 = v11;
      if( v11 < 0x20 )
        v4 = 32;
    }
    v11 = v4;
  }
  v5 = KeyHandle;
  *(_DWORD *)(a1 + 16) = v4;
  if( v5 )
    return ZwClose(v5);
  return v4;
}

Referenced by:

EtwInitializeSiloState